It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…
Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/
Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
21–30 of 424 posts
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#22Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?
LineageOS has a moderately large selection of supported phones for a custom ROM and it has weekly updates. My two and a half year old Moto E has the October 5th security patches for Android.
But it has very few kernel security patches: https://cve.lineageos.org/android_kernel_motorola_msm8610
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#23Earlier quoted context omitted.
Not the first time OpenBSD does not respect embargoes, for example https://lwn.net/Articles/726585/ and https://lwn.net/Articles/726580/
As a user I am completely fine with that.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#24Is there a way I can install an open source phone OS on my old Android phones to keep them patched? I'm not prepared to keep buying new phones just because manufacturers only provide intermittent updates for a year or two. Anyone got any suggestions for options?
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#25Do we now need WPA3? No, luckily implementations can be patched in a backwards-compatible manner.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#26It seems that OpenBSD already patched their source code and that wasn't to the likings of the researcher. In the future he will now delay notifying OpenBSD of vulnerabilities. Why did OpenBSD silently release a patch before the embargo? OpenBSD was notified of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure…
This feels like some kind of prisoner's dilemma game theory problem. By defecting from the embargo, OpenBSD gained potential security for its users at the expense of all other users. Overall, this is a loss, unless you use OpenBSD. I have to agree with the researchers on this one; OpenBSD acted selfishly here.
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#27> This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. ... if transmitted over plaintext http
Or if combined with some other vulnerabilities...
Re: Key Reinstallation Attacks – Breaking WPA2 by Forcing Nonce Reuse
#28Do I have to update the both the AP and the client or is one of them enough?